risk-nexus/REGISTER.md
tegwick a05ca6822b RISK-WP-0005 finished: the seven gaps closed
T01 fix tracking now reads the owner's workplan file and found two
findings the register should have known about. T02 incident and external
report intake, the latter routed since the address is not ours to create.
T03 the production transition defined by what is held rather than what
was announced. T04 the README stops claiming a surface. T05 escalation
carries a delivery state and is raised once when unacknowledged. T06
checked_by and a heartbeat, so a 1q rung cannot silently mean nobody
looked. T07 coverage: 7 of 117 repos have ever appeared in a finding.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-21 08:34:30 +02:00

7.3 KiB

Register

Generated by tools/register_index.py from findings/. Do not edit by hand. Last built 2026-08-21.

8 live of 9 findings; 3 notes below the floor.

Findings

ID Finding System Severity Disclosure Escalation Fix owner Status Cadence Next check
RISK-F-0009 agent-high-risk-boundary denies 6 of 17 high-risk lanes; the direct bao path is unprotected for the rest railiance-platform high embargoed none railiance-platform open 1h (1) due
RISK-F-0008 The legal basis for retaining audit facts against an erasure request has been assumed, never established audit-core medium public answered (t2, answered) risk-nexus accepted instant (0) due
RISK-F-0007 No consumer's tenant boundary is verified anywhere estate high embargoed answered (t4, assigned) per-consumer, on request accepted instant (0) due
RISK-F-0006 apps-pg has no backup configured at all: R0 means no recovery railiance-platform high embargoed answered (t3, approved) railiance-platform open 1h (1) due
RISK-F-0005 audit-core read path applies no tenant filter; the bound is deployment, not code audit-core medium public none audit-core mitigated instant (0) due
RISK-F-0004 tenant-engine events() returns the entire event log unfiltered tenant-engine high embargoed none tenant-engine open 1h (1) due
RISK-F-0003 ops-warden agent read-boundary does not fire on ungraded catalog lanes ops-warden medium embargoed none ops-warden mitigated 8h (2) 2026-08-21 14:32Z
RISK-F-0002 ops-warden signs SSH certificates with no authorization decision, and its unblock is now unsafe ops-warden medium embargoed withdrawn (t6, withdrawn-hazard-window-closed) ops-warden open instant (0) due
RISK-F-0001 flex-auth /v1/check authenticates no caller flex-auth high public withdrawn (t1, withdrawn-before-sending) flex-auth fixed instant (0) due

Constraints

Hazards created by acting in the wrong order. Each binds another finding's remediation.

From Binds Severity Constraint
RISK-F-0002 RISK-F-0001 lifted LIFTED 2026-08-19 — flex-auth /v1/check now authenticates callers (RISK-F-0001 fixed). Enabling policy.enabled is now an availability question for ops-warden, no longer an attestation hazard.

Waiting on someone

Every wait resolves on its default date whether or not anyone answers. Silence never buys a softer grade — see docs/method/dependencies.md.

Finding Who What would change Default if silent On
RISK-F-0009 railiance-platform embargo lifts on coverage; live verification would refine the grade but is not required for it the eight uncovered paths stand as recorded and the finding is re-raised 2026-09-03
RISK-F-0008 audit-core a working keyed commitment narrows RISK-REG-0001 to retained-by-obligation categories only encrypt-then-hash recorded as the only known route, and the retention period recorded as unstateable 2026-11-17
RISK-F-0007 user-engine likelihood falls for user-engine if a verification exists; a defect becomes its own finding if not the on-request path is recorded as having produced no answer, which makes the acceptance itself unsupported and is escalated 2026-09-03
RISK-F-0006 railiance-platform embargo lifts on a demonstrated restore; the approved spend becomes a real figure recorded as stalled with approval already granted, which is the worst kind of stall 2026-09-18
RISK-F-0005 audit-core likelihood rises to L3 if any other production credential carries may_read graded on the sender alone, as stated; the wider question is recorded as unanswered 2026-09-19
RISK-F-0004 tenant-engine grade rises if the log carries tenant payload rather than metadata grade stands as recorded; absent fix tracking is recorded as a stall 2026-09-03
RISK-F-0002 ops-warden if it admits no ingress, enabling the gate stops all signing — an availability blocker, not a risk one the register records the ordering as unverified and re-raises it; the finding stands at medium 2026-08-27
RISK-F-0001 policy-nexus publication: published plus the permanent URL comes back onto each record the findings stay disclosure: public with no address, which the register records as a claim rather than a publication 2026-09-17

Embargoes

Held from publication with a stated condition. A hold with no moving condition is a stall.

Finding Since Lifts when Re-decided
RISK-F-0009 2026-08-20 railiance-platform reports the deny set covers every high-risk lane with a KV path (live verification refines the grade, it is not the condition)
RISK-F-0007 2026-08-19 a verification exists for at least one consumer boundary 2026-09-18
RISK-F-0006 2026-08-19 a backup exists and a restore has been demonstrated once 2026-09-18
RISK-F-0004 2026-08-19 the read path filters by tenant in code 2026-09-18
RISK-F-0003 2026-08-19 RISK-F-0009 resolved — the OpenBao deny set covers every high-risk lane with a KV path 2026-09-18
RISK-F-0002 2026-08-19 FLEX-WP-0015-T02 shipped and ops-warden policy.enabled true in production 2026-11-17

Notes (below the floor)

Seen, deliberately not findings. Not graded, not reviewed, not published.

ID Note Why below the floor
RISK-N-0004 No facility answers which zone a workload is in, or what applies there missing capability, not a defect — there is nothing to route to a fix owner, and the register does not file undone work
RISK-N-0003 Every defect in this register was found by reading, none by monitoring no owner and no defect — it is an argument about where to invest detection, and the register cannot route an argument
RISK-N-0001 Noisy-neighbour behaviour is uncharacterised no decision changes today — no tenant shares a saturating workload, and what is missing is measurement work, not a defect to route

How to read this

Severity is docs/method/severity.md; disclosure docs/method/disclosure.md; escalation docs/method/escalation.md; the check cadence docs/method/review.md. Cadence is the ladder rung and the count of consecutive clean checks — a finding at 1q (9) has held still for a long time; one at instant (0) moved recently. Anything wrong resets it. A constraint may be graded higher than the finding that carries it — read both.